Unity · Unity Privacy Policy · View original document ↗

SDK End-User Data Collection Without Direct Relationship

High severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Unity Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If you play a mobile game built with Unity's engine or using Unity's advertising SDK, Unity may collect your device ID, IP address, and gameplay behavior even though you never signed up for anything with Unity directly.

This analysis describes what Unity's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision affects potentially hundreds of millions of mobile game players who have no direct relationship with Unity but whose data Unity collects and uses for advertising profiling.

Consumer impact (what this means for users)

Players of Unity-powered games may have their device identifiers, IP addresses, and behavioral data collected and used to build advertising profiles without ever consciously agreeing to Unity's terms, raising questions about the adequacy of indirect consent in this context.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Opt Out of Arbitration
    Visit privacy.unity.com and submit an opt-out request for personalized advertising. You can also reset your device advertising identifier in iOS Settings under Privacy and Security or in Android Settings under Privacy to limit cross-app tracking.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Strava Medium

If we collect health information from these integrations (such as heart rate), we will not sell or use it for advertising or other similar purposes; we do not disclose it to third parties without your prior consent; and we will only use it for the specific purposes described in this Policy.

eBay Medium

We collect your personal data when you use our Services, create a new eBay account, provide us with information via a web form, add or update information in your eBay account, participate in online community discussions or otherwise interact with us.

See all platforms with this clause type →

Monitoring

Unity has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We collect data from end users of games and apps that are built using Unity's technology or that use Unity's services. This includes data collected through our SDKs, such as device information (including advertising identifiers), IP address, gameplay data and interactions, and other usage information. We may combine this data with other information we have about you.

— Excerpt from Unity's Unity Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision directly engages GDPR and UK GDPR, particularly the requirements around legal basis for processing and transparency obligations toward data subjects who have no direct relationship with Unity as controller. The policy cites legitimate interests as a basis for certain processing, which EU supervisory authorities have scrutinized in programmatic advertising and SDK-based tracking contexts. COPPA is also implicated where games accessible to children embed Unity's SDK. The FTC's authority over deceptive data practices is relevant for US-based end users. GOVERNANCE EXPOSURE: High. The collection of personal data from end users via embedded third-party SDKs, relying on legitimate interests or downstream developer consent, is one of the most actively scrutinized areas of EU data protection enforcement. The scale of Unity's SDK deployment amplifies regulatory exposure, and the adequacy of consent or notice provided to end users through the game publisher layer is operationally difficult to verify or guarantee. JURISDICTION FLAGS: EU and EEA users receive the highest protection under GDPR, and legitimate interests assessments for advertising-related processing face a high bar under EDPB guidance. California residents have CCPA and CPRA opt-out rights. Users in jurisdictions with sector-specific mobile privacy regulations (such as Illinois for biometric data if gameplay involves such collection) may have additional protections. COPPA creates heightened exposure where games are accessible to children under 13. CONTRACT AND VENDOR IMPLICATIONS: Game developers and publishers who embed Unity's SDK are likely subject to Unity's developer terms, which may include data processing agreements under GDPR Article 28. Procurement teams at publishing organizations should verify that adequate DPAs are in place, that their own end-user privacy notices disclose Unity's data collection, and that opt-out mechanisms are surfaced to players. COMPLIANCE CONSIDERATIONS: Compliance teams should map all products using Unity's SDK and audit whether end-user privacy disclosures adequately reference Unity's data collection. Legitimate interests assessments covering SDK-based advertising data collection should be reviewed and documented. For EU-facing products, consent management platform configurations should be evaluated to ensure Unity's processing is covered within the IAB TCF consent string or equivalent mechanism.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive data practices affecting US consumers, including undisclosed or insufficiently disclosed data collection via third-party SDKs in mobile applications.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
COPPA
United States Federal
Connecticut Data Privacy Act Amendments
US-CT
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Unity Privacy Policy
Entity
Unity
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 10, 2026
Record ID
CA-P-009028
Document ID
CA-D-00750
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
550d996279ea0b8c6b167a3612cad9e086dba07fd480d6eae9ba2449359871d6
Analysis generated
May 8, 2026 01:34 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Unity
Document: Unity Privacy Policy
Record ID: CA-P-009028
Captured: 2026-05-08 01:34:30 UTC
SHA-256: 550d996279ea0b8c…
URL: https://conductatlas.com/platform/unity/unity-privacy-policy/sdk-end-user-data-collection-without-direct-relationship/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Unity's SDK End-User Data Collection Without Direct Relationship clause do?

This provision affects potentially hundreds of millions of mobile game players who have no direct relationship with Unity but whose data Unity collects and uses for advertising profiling.

How does this clause affect you?

Players of Unity-powered games may have their device identifiers, IP addresses, and behavioral data collected and used to build advertising profiles without ever consciously agreeing to Unity's terms, raising questions about the adequacy of indirect consent in this context.

Is ConductAtlas affiliated with Unity?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Unity.